High severity7.8NVD Advisory· Published Sep 2, 2022· Updated Jun 17, 2026
CVE-2021-25657
CVE-2021-25657
Description
A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate privileges. This issue affects Admin Lite and USB Creator 11.1 Feature Pack 2 Service Pack 1 and earlier versions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
90+ 6 more
- (no CPE)range: 0
- cpe:2.3:a:avaya:ip_office:*:*:*:*:*:*:*:*range: <11.1
- cpe:2.3:a:avaya:ip_office:11.1:-:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office:11.1:feature_pack1:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office:11.1:feature_pack1_service_pack1:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office:11.1:feature_pack2:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office:11.1:feature_pack2_service_pack1:*:*:*:*:*:*
- Range: <=11.1 Feature Pack 2 Service Pack 1
- Range: <=11.1 Feature Pack 2 Service Pack 1
Patches
Vulnerability mechanics
References
2- support.avaya.com/css/P8/documents/101083319nvdPatchVendor Advisory
- github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0037/MNDT-2022-0037.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.